Privacy Policy

Responsible Authority

We are happy about your visit to our website. We would like to introduce ourselves as the responsible authority within the meaning of data protection law:

Atelier Bäcker
Sole proprietor Alexandra Baecker
c/o Impact Hub Zürich AG, Sihlquai 131
8005 Zürich

Switzerland
E-mail: [email protected]

General Information

Pursuant to our statutory obligations, we would like to inform you about the collection and use of your personal data.

When you use our website, personal data about you will be collected. This may happen by you entering the data yourself, for example your e-mail address. But our system also collects your data automatically, for example whenever you visit our website. This happens irrespective of the device or the software that you use to visit our website.

All data that you enter in our app is provided voluntarily; there are no disadvantages to you if you do not provide data. But without certain data, we are unable to provide services or to conclude contracts. Whenever such information is necessary, we will point it out to you.

On this website, the user’s personal data is only collected within the framework of the existing data-protection law, in particular the General Data Protection Regulation (GDPR). The legal terms used in the text are defined in Art. 4 of the GDPR.

The GDPR allows data processing in three cases in particular:

  • in accordance with Art. 6 para. 1 (a) and 7 GDPR, when you have consented to us processing your data; in this Privacy Policy and in the cases of consent pursuant to Art. 4 no. 11 GDPR, we will inform you in detail and each time for what purposes and under what circumstances your data will be processed by us;
  • in accordance with Art. 6 para. 1 (b) GDPR, when processing your personal data is necessary for negotiating, concluding or performing a contract;
  • in accordance with Art. 6 para. 1 (f) GDPR, if the balancing of interests leads to the conclusion that the processing is necessary to protect our legitimate interests; this means in particular our interests to analyse, optimise and secure the offers on our website – meaning primarily the analysis of user behaviour, setting up profiles for advertisement purposes and storage of access data as well as the use of third-party providers.

Inventory Data

We collect inventory data as far as it is necessary to establish, negotiate or amend a contract (including one without remuneration) between us and the user. This can be: customer data (for example name, address), contact data (for example e-mail address, phone number), service data (for example services ordered, duration, payment). Upon establishing the user relationship, we will ask you for this data (for example name, address and e-mail address) and will also tell you which of the information is required to establish the user relationship.

Usage Data

We also collect usage data to allow users to use the services on our website. These may consist of: usage information (for example visited websites or parts, duration of visit, interest in services), content data (for example data, text, images, sounds, videos entered or uploaded by you), meta data (for example identity of your device, location, IP address).

We will only combine usage data if and insofar as it is necessary for billing purposes. Otherwise, we will only put together usage data pseudonymously and only insofar as you have not objected. You may send this objection to the address indicated in the “About Us” section or the responsible authority indicated in this Privacy Policy at any time.

The legal basis for this data processing are our legitimate interests pursuant to Art. 6 para. 1 (f) GDPR in analysing the website and your use, possibly also the statutory permission to store data as part of the negotiation of a contract pursuant to Art. 6 para. 1 (b) GDPR.

Furthermore, our provider stores information, the so-called server log files, each time the website is used; this is information which is automatically transferred by your browser. In detail, this data consists of:

  • your IP address
  • type and version of your browser
  • host name
  • time of visit
  • the page from which you came to our page
  • name of the page opened
  • exact time of usage as well as
  • the amount of data transferred

This data will only be used for statistical purposes and do not allow us to identify you as a user.

Advertisements

Before sending you advertisements, we will ask for your explicit consent pursuant to Art. 4 no. 11 GDPR, except in cases of advertisements for similar products to the one you already acquired. This will happen in particular when you grant us consent to mail our newsletter or when you fill out a contact form.

You may withdraw your consent at any time in accordance with the subsequent section “Consent”.

INSOFAR AS WE USE YOUR PERSONAL DATA FOR DIRECT MARKETING, YOU MAY ALSO OBJECT TO THE USE OF YOUR DATA FOR THAT PURPOSE AT ANY TIME. THIS MAY BE DONE THROUGH ANY OF OUR MEANS OF CONTACT, PARTICULARLY BY E-MAIL TO THE E-MAIL ADDRESS LISTED IN THE “LEGAL NOTICE” SECTION WITHOUT ANY FORMAL REQUIREMENTS. WE WILL THEN NO LONGER USE YOUR DATA FOR DIRECT MARKETING.

First Contact through Electronic Request

If you contact us in electronic form (for example by mail, fax, phone, messenger, etc.), we store and process the data which you have given us (for example name, contact information, content of the request). This is based on our legitimate interest in an effective communication with customers in accordance with Article 6 para. 1 (a) GDPR and, as far as it concerns a request to enter into or to perform a contract, also with Article 6 para. 1 (b) GDPR.
We will only pass on this data to third parties as far as required for the performance of the contract (in accordance with Article 6 para. 1 (b) GDPR), by the overwhelming interest in effective services (in accordance with Article 6 para. 1 (f) GDPR) or based on your consent (in accordance with Article 6 para. 1 (a) GDPR) or if there is another legal permission or obligation.
You may ask us at any time and without any cost to provide information about the purpose of the processing, the origin and the recipient, if any, of your data. You may also request that we correct, delete or limit the processing of your personal data. You may object against the (further) processing of your data at any time and you have a right for the data to be made transferable as well as the right to file a complaint with the competent supervisory agency.
In general, your data will only remain stored as long as required by the purpose of the respective data processing. A longer storage is an option, in particular when required in order to pursue our rights, for other legitimate interests of ours or when there is a statutory duty to keep the data longer (for example record-keeping under tax law, statute of limitations).

Consent

Whenever we ask you for your consent for the processing of your data, we will inform you in clear language and in an easily accessible way about the cases for which you will be granting your consent. Any consent that we ask you for is voluntary. Any advantage that you wish to gain by granting consent is also available without consent; simply ask us.

Regarding any consent, you have the right to revoke any consent given to us for the processing of your personal data at any time. You just need to contact us without any particular formal requirement, for example through our contact form, an e-mail to the e-mail address indicated in the “About Us” section or a link to unsubscribe (if offered by us). Your withdrawal has no effect on the legality of the data processing carried out up to that point.

Storage Period

Generally, your data will only remain stored as long as required by the purpose of the respective data processing. Storage beyond that is possible in particular if it is still required for pursuing our rights or for other legitimate interests of ours.
For your inventory data which were necessary to perform a contract (including one without remuneration), this means that we store this data until the complete performance or termination of the contractual relationship plus the limitation period (which is generally 2 or 3 years) plus an adequate extra time for potential interruptions of the limitation period.
For your usage data which was collected in the course of your use of the website, this means that we will store it only for the time still required for the proper functionality of our website and as long as we still have a legitimate interest. Statistical information will be primarily stored by us in pseudonymous form.
Beyond that, we still store your data for as long as we are required to do so by law. This concerns in particular the tax-law requirements to keep records, usually for 6 or even 10 years.

Based on our legitimate interest in a flawlessly functioning online offer and its economic and efficient design and optimization according to Article 6 para. 1 (f) GDPR, our website uses cookies in order to allow you to use our offer better, more effectively and in a more secure way. Cookies are text files that are stored on your computer and which store certain data about your user behavior on our page, so that certain features or offers can be made available to you based on your previous use. These can be “session cookies”, which are automatically deleted when you leave our website. Other cookies are stored on your computer permanently until you delete them. That allows us to recognize your browser when you visit our website again and to provide you with features or offers according to your previous usage.
Your browser allows you to prevent the use of cookies in general or in specific cases. Please check the instructions for your browser to find out more about this. You can also delete cookies following these instructions which we have listed for you:

for Chrome: https://support.google.com/chrome/answer/95647?co=GENIE.Platform%3DDesktop&hl=en
for Safari: https://support.apple.com/en-gb/guide/safari/sfri11471/mac
for Firefox: https://support.mozilla.org/en-US/kb/clear-cookies-and-site-data-firefox
for Edge: https://support.microsoft.com/en-gb/help/17442/windows-internet-explorer-delete-manage-cookies
for Internet Explorer: https://support.microsoft.com/en-gb/help/278835/how-to-delete-cookie-files-in-internet-explorer

Blocking cookies may limit the functionality of our website and of other websites visited by you.
More information on this topic, in particular how you can administer, limit or completely disable third-party cookies and technologies with a similar purpose, can be found at:
http://www.aboutads.info/choices
http://www.youronlinechoices.eu
http://www.networkadvertising.org/choices

Users‘ Rights

You may request us anytime to provide information about the personal data stored about you free of charge. To avoid misuse, this will require personal identification.

Deletion, Correction, Limitation

You may at any time demand from us that we correct (or complete) incorrect data as well as a limitation of the processing of data or deletion of your data. This applies in particular if the reason for processing the data is no longer valid, if a required consent has been revoked and there is no other legal basis or if our data processing is unlawful. We will then correct, block or even delete your personal data without delay as far as permitted by law.

Objection

The right to object to advertisement is governed by our text regarding consent:

Regarding any consent, you have the right to revoke any consent given to us for the processing of your personal data at any time. You just need to contact us without any particular formal requirement, for example through our contact form, an e-mail to the e-mail address indicated in the “About Us” section or a link to unsubscribe (if offered by us). Your withdrawal has no effect on the legality of the data processing carried out up to that point.

Data Transfer

You may request us to transfer the data stored about you in machine-readable form.

Complaint

If you feel that our data processing has violated any of your rights, you may file a complaint with the competent regulatory agency (here you find a list of the agencies).

Changes to the Privacy Policy

If and when factual or legal reasons will compel us to amend the Privacy Policy, we will update this page accordingly. This will not change the consent provided by the user.

Data Entry

Encryption of Data Entry

When you enter data on our website, whether in a contact form, during the registration process, when you log in or for payment purposes, the website, where you enter the data, is encrypted. Thus, third parties can not read what you enter. You will recognise the encryption by the lock symbol in your browser and by the URL beginning with “https“ instead of “http“.

Contact Forms

General contact form

When you fill out a contact form or when you send us an e-mail or another electronic message, your information will be stored for the processing of the request, for possible follow-up questions or for other related questions and will only be used to follow up with the request.

Your data will be transferred in an encrypted manner, preventing third parties from reading your data while it is being entered.

Basis for this storage is your consent pursuant to Art. 6 para. 1 (a) GDPR, which you grant us by filling in the contact form or by your other requests. You may revoke this consent at any time, you just need to contact us without any particular formal requirement (for example in the contact form or by e-mail). This withdrawal has no effect on the legality of the data processing that has occurred up to that point.

Your data remains stored for as long as the processing of the request requires, in particular as long as the storage is still necessary to perform the contract, to pursue our rights or for our other legitimate interests or we are compelled by law to keep your data stored (for example based on tax-law requirements to maintain files).

Newsletter

ConvertKit LLC

If you subscribe to the newsletter offered on our page, we will inform you in detail about the information we will send you, which of your data will be stored and for what it will be used. We will not pass on your data to third parties and we will only use it for mailing the newsletter.

We will only mail you the newsletter if you have provided us with prior consent. To that purpose, you will receive an e-mail from us with a link and further details and we will ask for your consent. By confirming that link, you declare your consent to receive the newsletter and advertisement from us.

The basis for the storage is your consent pursuant to Art. 6 para. 1 (a) GDPR, which you grant us when you register for the newsletter. You may withdraw that consent at any time, for which any notice to us, without any formal requirement, is sufficient (for example through the contact form or by e-mail or by using the link to unsubscribe, which is included in each e-mail). This withdrawal has no effect on the legality of the data processing carried out up to that point.

Because we are legally required to record your consent as part of the double opt-in, your subscription to the newsletter, the mailing of our consent e-mail and your consent by clicking on the link will be recorded and stored with location and time as well as with your IP address.

For mailing the newsletter, we use (as part of our legitimate interest in a technologically perfect processing of our customer data and analysis) the provider

https://convertkit.com/.

Thus, your data will be forwarded to the USA, but our newsletter provider is registered with Privacy Shield and must adhere to EU data protection rules.

In our newsletter, we will also explicitly ask you to provide your consent to transmitting data to our newsletter provider and to the USA. You will declare this consent by clicking on the link, but you may revoke it at any time. For the handling of your data by our newsletter provider, we refer you to our newsletter provider’s privacy policy (insert link). Our newsletter provider will only use your data for mailing the newsletter and for evaluating that mailing on our behalf. In addition to that, our newsletter provider will only use your data to improve its own service. But our newsletter provider will not use the data to contact you directly or to pass on your data to third parties.

The mails used by our newsletter provider contains a “web beacon“, which will inform our newsletter provider about the opening of the newsletter and/or the clicking on a link contained therein by you. As part of that process, information regarding your browser, your location and your IP address will be transmitted to our newsletter provider. This information will be used to optimise our communication with you.

Our newsletter provider will also use this data, but only in a pseudonymous form (meaning that they cannot identify you) to analyse and optimise their own services. Your data will never be used by the newsletter provider in order to contact you.

Your data will remain stored for as long as you are in our mailing list, as long as the storage is required to enforce our rights or as long as it is necessary for our legitimate interests or as long as we are required by law to keep your data stored.

Social Media

We refer with links to our social media presences. When you follow any such link to the social media site, your data will be broadcasted to that site. The social media site will normally store a cookie in your browser and to your account information there, especially, if you are logged into your social media account on the site. The social media site can analyse your use of the platform and your browsing habits and will use these for targeting advertisements based on your interests. That can lead to ads being shown to you when browsing in- and outside of the social media site. Please inform yourself about the use of your data on these sites and use them only, when you agree to that use of your data, that happens on that social media site, in particular, when you are not using that social media site for the first time. We have added links to all the privacy policies of the social media site for your information.

Our website uses links to our presence in the social network of Facebook by Facebook Inc., 1 Hacker Way, Menlo Park, California 94025, USA. It is just a normal link. Thus, when you open our site, Facebook will not learn of your visit to our website. But once you click on the link, you will be led to Facebook, allowing Facebook to learn that you have visited out site.

That way, your data will be transferred to the USA, but Facebook is registered with Privacy Shield and must adhere to the EU data protection rules.

The collection and use of your data which is possibly carried out by Facebook after clicking on the link is beyond our knowledge or control. You may find further information in Facebook’s privacy policy at http://de-de.facebook.com/policy.php.

Our website uses links to our presence in the social network of Instagram by Instagram LLC, now
Facebook Ireland Ltd.
4 Grand Canal Square
Grand Canal Harbour.

It is just a normal link. Thus, when you open our site, Instagram will not learn of your visit to our website. But once you click on the link, you will be led to Instagram, allowing Instagram / Facebook to learn that you have visited out site.
That way, your data will be transferred to the USA, but Instagram is registered with Privacy Shield and must adhere to the EU data protection rules.

The collection and use of your data which is possibly carried out by Instagram/Facebook after clicking on the link is beyond our knowledge or control. You may find further information in Instagram’s privacy policy at
https://help.instagram.com/155833707900388.

Our page uses links to our presence on the social network Pinterest, provided by Pinterest, Inc., 808 Brannan St, San Francisco, CA 94103, USA.

It is just a normal link, which means that upon opening our page, Pinterest won’t learn anything of your visit to our website. But when you click on the link, you will be taken to Pinterest, and then Pinterest will also learn that you visited our page.

Thus, your data will be forwarded to the USA, but Pinterest is registered with Privacy Shield and must adhere to EU data protection rules.

We have neither knowledge of, nor any influence on the possible collection and processing of your data by Pinterest. Further information can be found in Pinterest’ privacy policy at https://policy.pinterest.com/privacy-policy.

Online calendar

Calendly

Based on our legitimate interest in a technologically perfect online offering and its design and optimization in an economically efficient manner pursuant to Art. 6 para. 1 (f) GDPR, we use the calendar of Calendly https://calendly.com/de, a service offered by Calendly LLC, 1315 Peachtree St NE, Atlanta, GA 30309, USA, to make appointments.

Thus, the data you enter while making an appointment will be passed to Calendly. Your data will be transmitted to the USA in that process. But Calendly has subjected itself to the Privacy Shield framework. You can find more information about your rights thereunder at http://ec.europa.eu/justice/data-protection/document/citizens-guide_en.pdf .
You can find more information about the privacy policy of Calendly at https://calendly.com/de/pages/privacy. We have also entered into a contract on data processing with Calendly, according to which Calendly will only process your data according to our instructions.

In order to arrange an appointment, we ask for the data requested in the Calendly form and we collect your IP address at the time of entry. This data will not be passed to third parties by us or by Calendly and only serves statistical purposes and for arranging appointments. Data entry will be encrypted, preventing third parties from reading your data while you enter it. You will find more information about the data collected by Calendly and how they process your data in the privacy policy of Calendly .

Your data will remain stored as long as the reason for the appointment is still relevant, in particular as long as the storage is still necessary to perform the contract, to pursue our rights or for other legitimate interests of ours or as long as we are required by law to keep your data stored (for example by tax-law requirements on the keeping of records). If the appointment passes without any consequences, your data will be deleted.

Payment providers

PayPal

If you choose one of the payment options of our partner PayPal, provided by PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg, the data entered by you when ordering will be sent to PayPal in order to facilitate the contractual payment. Detailed information about this can be found in the privacy policy of PayPal: https://www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=de_DE

The legal basis for passing on your data to PayPal is primarily the processing of your contractual data according to Art. 6 para. 1 (b) GDPR as well as our legitimate interest in a technologically perfect online offering and its design and optimisation in an economically efficient manner pursuant to Art. 6 para. 1 (f) GDPR.

Stripe

If you choose one of the payment options of our partner Stripe, provided by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, the data entered by you when ordering will be sent to Stripe in order to facilitate the contractual payment. Detailed information about this can be found in the privacy policy of Stripe:

https://stripe.com/privacy

The legal basis for passing on your data to Stripe is primarily the processing of your contractual data according to Art. 6 para. 1 (b) GDPR as well as our legitimate interest in a technologically perfect online offering and its design and optimisation in an economically efficient manner pursuant to Art. 6 para. 1 (f) GDPR.

Various

Zoom.us (online webinars)

Based on our legitimate interest in a technologically perfect online offering and its design and optimization in an economically efficient manner pursuant to Art. 6 para. 1 (f) GDPR, we use the the provider Zoom.us, offered by Zoom Video Communications Inc., 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA, for online meetings and webinars.
If you participate in an online meeting, the data you enter upon registration will also be sent to Zoom. But Zoom will not use this data for its own purposes. You will only be reminded of the event for which you registered.
As organizers of the meeting or the webinar, we may make recordings and store them for ourselves. With your registration, you declare your consent to the recording and to our use thereof, but usually no personal data of yours will be revealed (you can also register under a pseudonym). That would only happen if you were to participate with your image. In that case, we would ask for your consent to use your image.
As we pass data to Zoom, the data will be sent to the USA, but Zoom is registered with Privacy Shield and must adhere to EU data protection rules.
We have no knowledge about the possible collection and use of your data by Zoom, nor do we have any influence on that. More information can be found in the privacy policy of Zoom at https://zoom.us/privacy. For the general approach to cookies and about their deactivation, we refer you to our general information about cookies in this privacy policy.

This is our current valid privacy policy from 22.04.2020